
SANS Internet Storm Center Highlights Persistent SSH Attacks and Critical Vulnerabilities
The May 19, 2026, SANS Internet Storm Center Stormcast episode highlights persistent SSH brute-forcing bots that install modified authorized_keys files as backdoors, with attackers now using an updated libssh library and altered hash values to evade detection. Microsoft disclosed an unpatched cross-site scripting (XSS) vulnerability in Exchange Server 2016, 2019, and the current subscription edition, actively exploited in the wild, with a workaround available for updated systems but causing minor calendar functionality issues. A recent Microsoft Authenticator update for iOS and Android fixes a flaw where attackers could steal authentication tokens via malicious websites, bypassing two-factor authentication. Additionally, a Linux privilege escalation vulnerability allows access to private SSH keys and the /etc/shadow file, enabling server impersonation, requiring kernel patches and reboots. The episode emphasizes avoiding over-reliance on specific indicators of compromise (IoCs) for SSH attacks and prioritizing workarounds for critical vulnerabilities despite minor side effects.